
Codeless Cloud Starter Sites Security & Risk Analysis
wordpress.org/plugins/codeless-cloud-starter-sitesA cloud based service with 30+ templates and starter sites for Specular theme.
Is Codeless Cloud Starter Sites Safe to Use in 2026?
Generally Safe
Score 85/100Codeless Cloud Starter Sites has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "codeless-cloud-starter-sites" plugin v1.0.1 exhibits a generally strong security posture based on the provided static analysis. It demonstrates excellent practices by utilizing prepared statements for all SQL queries and properly escaping all outputs. The plugin also incorporates capability checks, indicating an awareness of user permissions. Furthermore, the absence of known CVEs and any recorded historical vulnerabilities is a significant positive indicator, suggesting a commitment to security or simply a lack of discovered issues to date. The limited attack surface, with no discoverable AJAX handlers, REST API routes, shortcodes, or cron events without appropriate checks, is also commendable.
However, a notable concern arises from the complete lack of nonce checks. While capability checks are present, nonces are a critical defense-in-depth mechanism against Cross-Site Request Forgery (CSRF) attacks. Their absence leaves the plugin potentially vulnerable if any of its functionalities can be triggered by external, unauthenticated requests. The taint analysis showing zero flows with unsanitized paths is positive, but it's important to remember that taint analysis effectiveness can vary, and the lack of nonce checks is a more direct and concerning finding. In conclusion, the plugin is well-coded with strong data handling and escaping practices. The main area for improvement and potential risk lies in the implementation of nonce checks to bolster its defenses against CSRF threats.
Key Concerns
- Missing nonce checks
Codeless Cloud Starter Sites Security Vulnerabilities
Codeless Cloud Starter Sites Code Analysis
SQL Query Safety
Output Escaping
Codeless Cloud Starter Sites Attack Surface
WordPress Hooks 17
Maintenance & Trust
Codeless Cloud Starter Sites Maintenance & Trust
Maintenance Signals
Community Trust
Codeless Cloud Starter Sites Alternatives
Starter Sites & Templates by Neve
templates-patterns-collection
This plugin gives you access to 100+ templates and ready-to-use starter sites. Neve theme is used for all the designs.
Extendify
extendify
The best WordPress templates, pattern, and layout library with 1,000+ designs built for the Gutenberg block editor.
Qi Blocks
qi-blocks
Qi Blocks is the largest collection of Gutenberg blocks developed by Qode Interactive.
BlockSpare — News, Magazine and Blog Addons for (Gutenberg) Block Editor
blockspare
Highly customizable Gutenberg blocks and starter templates to build blogs, magazines, and business websites. Create post grids, sliders, filters, and …
Blocks Starter Templates
blocks-starter-templates
Starter templates and patterns library. Ready-to-use Gutenberg templates that work with every theme. Created only with in-built WP blocks.
Codeless Cloud Starter Sites Developer Profile
7 plugins · 2K total installs
How We Detect Codeless Cloud Starter Sites
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/codeless-cloud-starter-sites/assets/build/style-app.css/wp-content/plugins/codeless-cloud-starter-sites/assets/build/app.js/wp-content/plugins/codeless-cloud-starter-sites/assets/build/app.jscodeless-cloud-starter-sites/assets/build/style-app.css?ver=codeless-cloud-starter-sites/assets/build/app.js?ver=HTML / DOM Fingerprints
coss-appcossDash/wp-json/codeless-starter-sites/v1/sites